The tool presented below tries to detect from remote if the target machine was compromised with the HACKER Defender rootkit. The tool connect to the remote host, and compares the reply to several known replies. The rootkits that can be detected by the tool are: HACKER Defender v1.0.0 and below.
rootkit技術,歡迎下載,英文書名:rootkits:Subverting the Windows Kernel
計算機安全圖書中第一本關于終極后門程序——Rootkit的詳盡指南!
世界級軟件安全專家、rootkit.com創始人Greg Hoglund教您全面掌握rootkit,提升自己的安全防范能力
This material is not only up-to-date, it defines up-to-date. It is truly cutting-edge. As the only book on the subject, rootkits will be of interest to any Windows security researcher or security programmer. It s detailed, well researched and the technical information is excellent. The level of technical detail, research, and time invested in developing relevant examples is impressive.